Sentrix

Framework · GDPR

GDPR: Article 32, DPIAs and data subject rights, all mapped

The EU regulation for any organization processing data of EU residents: lawful basis, DPIAs, data subject rights, Article 32 measures and processor contracts.

The General Data Protection Regulation applies to any organization processing personal data of EU residents, regardless of where the organization is located. The data protection authorities (DPAs) of each member state enforce it and issue fines of up to 4% of global annual turnover. GDPR is both a data protection regulation and a technical security framework.

Key facts

  • 72 h: maximum time to notify the supervisory authority after discovering a personal data breach (Art. 33).
  • 4%: cap on administrative fines, as a share of global annual turnover (Art. 83).
  • Art. 32: technical and organizational security measures appropriate to the risk.
  • Art. 44–49: safeguards for international transfers, including standard contractual clauses and adequacy decisions.

What GDPR requires

Article 32 requires appropriate technical and organizational security measures based on risk. Articles 33–34 require breach notification within 72 hours. Articles 13–22 establish data subject rights your organization must honour.

  1. Art. 5: processing principles; purpose limitation, data minimization, accuracy
  2. Art. 6: lawful basis for processing; consent, legitimate interests, legal obligation documented
  3. Art. 13–14: information to be provided; privacy notice records
  4. Art. 17: right to erasure; deletion workflows and documentation
  5. Art. 32: security of processing; encryption, pseudonymization, resilience
  6. Art. 35: DPIA required before high-risk processing projects

What Sentrix provides for GDPR

Article 32 technical controls

Sentrix maps the technical controls required by Article 32, encryption at rest and in transit, access control and MFA, audit logging, disaster recovery plan, to evidence drawn from your infrastructure.

Records of Processing Activities (Art. 30)

Article 30 requires a documented record of all processing activities. Sentrix maintains your ROPA as new integrations and processing activities are detected across your infrastructure.

Data Protection Impact Assessment (Art. 35)

Bilingual DPIA templates, completion tracking, assessments stored as audit evidence and alerts when new projects trigger the obligation to carry one out.

Data subject rights management

Track access, rectification, erasure, and portability requests within the one-month response time. Request logs maintained automatically and reminders before deadlines.

72-hour breach notification

Breach classification workflow, DPA notification templates, and data subject notification documentation. All evidence archived in the format DPAs expect during investigations.

Processor agreement management (Art. 28)

Article 28 requires a contract with every processor. Sentrix tracks all your processor agreements, expiry dates, and audit requirements, with alerts before expiry.

Crosswalks

  • Law 25: significant overlap (consent, DPIA and PIA, breach notification, data subject rights), mapped for organizations managing both regimes.
  • PIPEDA: Canada holds an adequacy decision; PIPEDA controls are mapped to GDPR requirements.
  • NIS2: Article 21 security measures for EU essential and important entities.
  • ISO 27001: Annex A controls address the Article 32 security measures.
  • HIPAA: for healthcare organizations serving patients in the United States and Europe.

Further reading

SaaS and technology solution and healthcare solution.

See your GDPR posture and Article 32 gaps.

Contact us

Frequently asked questions

Who does the GDPR apply to?
The General Data Protection Regulation applies to any organization that processes personal data of residents of the European Union, regardless of where the organization is located. A Canadian or US company with customers or users in the EU is therefore subject to it. The data protection authorities of each member state enforce it and can issue fines of up to 4% of global annual turnover.
What is the deadline to notify a personal data breach?
Articles 33 and 34 require notification of the supervisory authority within 72 hours of discovering a personal data breach and, where the risk to individuals is high, communication to the data subjects. Sentrix provides a breach classification workflow, authority notification templates and data subject communication documentation, archived in the format expected during investigations.
What is a DPIA and when is it required?
A Data Protection Impact Assessment (DPIA) is required by Article 35 before any processing likely to result in a high risk to the rights and freedoms of individuals. Sentrix provides bilingual DPIA templates, tracks completions, stores assessments as audit evidence and alerts when new projects trigger the obligation to carry one out.

Let's talk about your compliance program.

Last updated: 2026-09-17